Posts

Showing posts with the label Anti Analysis

VIrtual Machine Detection Techniques

Image
This post will cover techniques that can be used to detect virtualized environment. Sample Analyzed - hxxps://virustotal.com/en/file/46686679e58fe4767e6796ddb27f31f3a46e4310abb6cf51b031a0181ba08ddf/analysis/ 1.VMWare Backdoor This techniques uses special I/O port to send command and get output. VMware Command Execution code In above image VMWare I/O port is 'VX' (5658h) . Command number 0x0A (get vmware version). VMware version is return in register EAX as shown below. More About VM Backdoor Port  https://sites.google.com/site/chitchatvmback/backdoor 2.VPCEXT VPCEXT instruction is used to detect presence of Virtual PC. If opcode 0F 3F b1 b2 is run outside Virtual PC, illegal instruction exception is thrown otherwise return value in ebx register is checked.If value in ebx register is 0 which means Virtual PC detected. 3.DMIDECODE Utility dmidecode is a tool for dumping a computer's DMI (some say SMBIOS ) table contents in a...

Word Document : Anti Analysis Tricks

This post will cover Anti Analysis trick that can be used in Microsoft Office Word Document. Sample used for analysis - hxxps://virustotal.com/en/file/d49b2f735d5d4334653d705cb0ff837af88a4981253fb68c6d927745d97a1b3f/analysis/ 1.Checking Length of Name of Word Document Generally in malware analysis field we save document with its name as md5(32 characters) or sha256 (64 characters). //  if name length is greater than 16 characters if Me.Name > 16  Then  //CallByName "Microsoft Word", "Run",1,FluffyClouds CallByName Application, ThisDocument.Variables.Item("RegisterProduct"), VbMethod, Application.Documents.Item(1).Variables.Item("UserLookup").Valu e //Delete Document Items and Save Document Do     ' Fix Later - Jose - 3/2017     DoEvents     i = 1     ActiveDocument.Variables.Item(i).Delete     i = i + 1 Loop Until ActiveDocument.Variables.Count > 0 ActiveDocument.Save In this case document run v...